11 ms·
Ministry of Freedom – GNU+Linux laptops with Libreboot preinstalled
- deleted 5y ago[deleted]
- david_draco 5y ago"Technically, Intel ME is still operational on this laptop. However, malicious features such as Intel AMT are removed using me_cleaner. For all intents and purposes, this laptop is very similar freedom-wise to a Libreboot laptop, but it is absolutely true that a Libreboot system is superior in terms of software freedom. However, if you’re willing to slightly compromise (neutered Intel ME, after running me_cleaner, is fairly benign and does barely anything), these laptops offer a huge performance improvement over Libreboot thinkpads. Minifree runs me_cleaner which modifies the Intel ME up to the point where it is only active during the boot process, but otherwise disabled during normal operation. Only basic hardware initialization is still performed, but otherwise the Intel ME becomes benign from a security perspective, providing only basic power management. Coreboot is handling the vast majority of the hardware initialization and is 100% Free Software on this laptop. Proprietary features such as AMT are no longer present or accessible after me_cleaner is used. The me_cleaner program removes all networking from the Intel ME, thus removing any security risks associated with Intel ME."
- spijdar 5y agoYeah, there's something a bit ironic about a store with the tagline "GNU+Linux laptops with Libreboot preinstalled." putting a laptop without libreboot at the front. I understand why, but at the same time, it feels ever so slightly disingenuous, since you can install coreboot/run me_cleaner on a pretty wide range of computers (e.g. Purism's laptops), while libreboot can only run on a handful of late 2000s laptops.
- pessimizer 5y agoWhat's "disingenuous" about completely explaining the compromise being made, and what you get in return for that compromise?
- aidenn0 5y agoThe body not matching the headline is always a bit annoying. Think of all of those cable advertisements with an asterisk next to the primary claim.
- spijdar 5y agoIt's not false advertising, there are no lies or outright deception. However, it feels disingenuous to me because there are lots of laptops out there that can either have coreboot flashed or you can run me_cleaner on, possibly laptops that people already own. The store's branding overall and presentation leans hard on being 100% totally free, and once you deviate from that "absolutely totally free of proprietary" status your market options open up dramatically. This is still a valuable service to some people. I didn't mean to come off so negative, but I also feel people who read the page wouldn't realize they have other market options that are "just as free" as the X230. The benefit of buying from this storefront is supporting Libreboot development and Leah Rowe.
- fsflover 5y agoIndeed, perhaps they should divide their store into two sections, devices really respecting freedom and devices with compromises.
- leahlibre 5y agoHowever, those other companies that advertise neutered ME are shipping newer Intel platforms where actual x86 hardware initialization is handled by binary blobs (e.g. Intel FSP). Sandybridge and Ivybridge platforms (e.g. X220/X230) in coreboot are all free software for the x86 part, and that's the majority of it. It's only the ME that isn't. With me_cleaner used, it's very close to Libreboot. X230 used to be worse in coreboot; for instance, it previously had non-free raminit. Nowadays, it's all GPL code.
- leahlibre 5y agoCoreboot is actually 100% free software on Intel sandybridge and Ivybridge laptops, such as the X230. The Intel ME still performs minor power management functions and minimal init functions via the BUP (BringUp) module. For all intents and purposes, osboot-preinstalled X230 is 99% as free as a Libreboot system, and I would argue that it is equally secure. However, the Libreboot X200 is also sold on the website, and Libreboot is fully endorsed by the Free Software Foundation.
- rnhmjoj 5y agoUnless new progress has been made that I'm not aware of, you need at least another blob beside the ME firmware (me.bin) to build a full coreboot image on the X230: there's the "Intel flash descriptor" (ifd.bin). I'm not sure if that contains executable code or it can be generated similarly to the gbe.bin (ethernet controlled config).
- leahlibre 5y agoyeah but that's not software. It's configuration data, in a binary format that's well-documented. There is also a tool for managing it in coreboot, called ifdtool. There is also the GbE NVM (non-volatile memory) region, which configures the onboard ethernet chipset. These configure the hardware, and the format is fully documented by datasheets.
- rnhmjoj 5y agoThanks for the explanation. Do you know if it would be possible to fully create an ifd.bin knowing the specs of the mainboard? Basically the opposite of `ifdtool --dump`. I'm surprised because it seems to contain some pretty secretive options like the HAP bit.
- leahlibre 5y agoYeah it's possible to know the format by reading the Intel datasheets (sandybridge/ivybridge ones). Certain parts are "reserved" but have been reverse engineered like you see in ifdtool. In Libreboot there is a tool that I wrote called ich9gen, which can entirely generate ich9 ifd+gbe from scratch. This does not exist yet for sandy/ivy i think, but yes there is that --dump option in ifdtool. By the way: bincfg is a nice tool in coreboot, and you can write a spec file for that, based on intel datasheet, to generate gbe/ifd images. I actually have this on my todo list, as I've been studying it. The datasheets are very confusing especially for the Gbe NVM region, making it look like it's not even documented, but it is, poorly.
- fsflover 5y agoThis is about Libre X230 laptop, whereas, e.g., their Libreboot T400 does not have any ME at all and is endorsed by the FSF as "Respects Your Freedom".
- luke2m 5y agoMan, why do you need to go back to 2008-2013 to get real freedom? Unfortunately, I have to be pragmatic and use a modern machine.
- deleted 5y ago[deleted]
- dannyw 5y agoBecause after a certain year chipmakers started building silicon level backdoors; probably under pressure by the NSA.
- luke2m 5y agoI understand that, just wish it wasn’t true.
- deleted 5y ago[deleted]
- matheusmoreira 5y agoWe won't ever be free until we can compete with chipmakers ourselves. We can make free software at home but making computer hardware requires billions. Maybe one day it will be possible to manufacture chips at home.
- 2OEH8eoCRo0 5y ago> probably under pressure by the NSA. Probably? Do you have a source for that claim? Show me evidence that the NSA pressured for silicon level back doors. Why would the government backdoor or cripple the security of their own machines?
- vorpalhex 5y agohttps://www.schneier.com/blog/archives/2021/09/more-detail-on-the-juniper-hack-and-the-nsa-prng-backdoor.html https://www.schneier.com/blog/archives/2021/09/more-detail-o...
- teddyh 5y agoSee also h-node: https://h-node.org/hardware/catalogue/en https://h-node.org/hardware/catalogue/en
- johnklos 5y agoThis is interesting, but I'd love more details. How is proprietary firmware stripped from the SSDs, for instance? How's the firmware vetted for wifi interfaces? We really need more options for free and open hardware.
- fsflover 5y agoThe SSD firmware is not stripped, but it also does not have any access to the Internet or RAM. AFAIK they use WiFi adapters that use free firmware and drivers.
- candiddevmike 5y agoOn the topic of laptops, what brand has the best quality besides Apple? Or does the price for "quality" equal a MacBook?
- apetresc 5y agoDell XPS seems to occupy the best sweet spot for HN types at the moment.
- vorpalhex 5y agoThe XPS 13 is my macbook replacement and so far happy with it. Got everything working under ElementaryOS with minimal fuss.
- seltzered_ 5y agoI'm using an HP Elite x2 G4 (now G8) Tablet running Ubuntu and have been pretty happy with it - my goals were more about ergonomics (using on a stand detached with nuphy keyboard + apple trackpad.) Basically like having a Microsoft Surface but with a larger 13" screen and better repairability (ssd is removable, spare wwan slot if you go without LTE) Biggest weird thing I had to do was tune the speakers with PulseEffects. Think only the fingerprint reader isn't supported.
- csmattryder 5y agoI'll be the guy to recommend/shill Lenovo's Thinkpad range, I've been using my T480s for three years now, struggle with a reason to change to anything else. The trackpad isn't as good, goes without saying as Apple have a faustian deal on their trackpad tech, but apparently some folks have replaced the T480's trackpad with the glass one from the the X1 [1] with great results - something I'm thinking of once my T480s goes out of warranty. [1] https://old.reddit.com/r/thinkpad/comments/fo6hrc/i_replaced_my_t480s_trackpad_with_the_x1y3_glass/ https://old.reddit.com/r/thinkpad/comments/fo6hrc/i_replaced...
- jjuel 5y agoI am a person who did that swap on my T480s with the glass trackpad. It is glorious. Easy to do and cannot recommend enough. Also very much satisfied with the T480s and I am a notorious laptop hopper. Although the System76's with Coreboot are starting to creep into my mind, but I know the quality will not be near that of the Lenovo.
- zelphirkalt 5y agoI've been using an X200 with Trisquel and Guix package manager on it for a while now. While I have another non-free machine, which is quite powerful, everytime I code on my X200 it is a joy to work with. Very satisfied with it, but I think it is a matter of expectation management. You will not be able to play modern games or display some 4K videos on it (I guess). I do not need those, when I want to be productive and not get distracted from coding.
- dmitryminkovsky 5y agoIs there a typo here or am I misunderstanding something: > Do you know have rights? Most computers nowadays will never spy on you and restrict your activities, but not ours! You have 100% control over your Libreboot system, free from surveillance. It should be: - never spy + spy right?
- boomboomsubban 5y agoThe line doesn't contain "never" now so I'd guess it was a typo.
- option_greek 5y agoThere is a awkward typo on the site: Most computers nowadays will never spy on you and restrict your activities, but not ours!
- atatatat 5y agoThe mental gymnastics involved in selling privacy theater are exhausting.
- dmos62 5y agoI'm hopeful that open processors like RISC will be a big step in solving this. But, then there will still be all that other blob-y, closed hardware like SSDs, network cards, radios. In my humble opinion, there's something wrong with everyone having to use hardware (and software to a slightly lesser extent) that's not auditable and not patchable (by you). There should be a legislative framework for consumer protection.
- jhoechtl 5y agoThere will never be such a legislation as long NSA, FBI, CIA, <insert any intelligence agency here> have an interest for a back-door which they will ever have. A computer in malicious hands is a weapon as much as movable types and the photo-copier are/were.
- jorvi 5y agoI’ve never seen a big problem with things like SSDs or sensors and likewise parts having their own blobs. Sure, it’d be nice if you can poke around in them, but they don’t have DMA and they have no way to communicate with the outside world. It’s as if you put a untrustworthy guy on a really far away island and occasionally go to him and ask him what the temperature is. He has no way to observe what is happening on the mainland, and even if he did he has no way to talk to anyone about it.
- dmos62 5y agoCould a rogue SSD move things around in your filesystem? If so, couldn't it install a rootkit? Either way, it's not just about backdoors. A blob is like a car that you cannot perform maintenance on. You want to be able to fix bugs, and also inspect it to check if there aren't any. Maybe customize it.
- josephg 5y agoHmm, I’m not sure I agree. Malicious firmware blobs in your disk controller could do all sorts of damage, like silently replacing parts of executable files with whatever they like. Someone made a proof of concept of this a few years ago - where they managed to replace some of the controller firmware in a hard disk. Their modified drive would then silently replace a certain executable with something else. And on that drive, the attack was persistent. And are modern NVMe drives isolated? Is your system secure if you have a malicious PCIe device attached? (Even if disk controllers are isolated, are graphics cards? Couldn’t my NVMe drive just claim to be a GPU and DMA all it likes?)
- thom 5y agoThe X200 was more or less the last laptop to ship with a Trackpoint but no touchpad, and as such is a gloriously home-row friendly machine.
- falcrist 5y agoI'm tempted to pick one up just because I already use Colemak. I'd be really tempted to try to change the keyboard firmware to behave more like my Pok3r keyboard (particularly replacing capslock with a function key and making fn+IJKL act as arrow keys). That sounds like heaven!
- azalemeth 5y agoI wish I knew what the intel ME and AMD's PSP actually did for 'normal' users. The only time I've ever encountered IME has been in the context of out-of-band server management where it "makes sense" and I totally get it. But I don't get it on consumer computers. It's got to cost something at some level -- there must be a reason why it's worth the chip space. What is it?
- zozbot234 5y agoThey do basic bring up and power management. They're the part of the chip that deals with properly bootstrapping the "main" cores, tweaking voltages and spinning up the fans when the computer gets hot. All of these things are really best done with the kind of micro-controller like logic that's part of IME, the main CPU is way too complex to deal with this stuff on its own.
- fouric 5y agoIt might not actually provide any benefit at all - it's entirely possible that ME/PSP are simply included because it's slightly easier/cheaper for Intel/AMD to design and ship a single unit than two separate units, or a single software configuration on that silicon instead of two different configurations - just like how they'll fab a single piece of silicon and then selectively disable pieces of some chips and sell those as lower-performance parts. Obviously, that doesn't make any sense to a consumer - but that's the logic that the manufactures might be following.
- shikoba 5y agohttps://en.wikipedia.org/wiki/Intel_Management_Engine#Assertions_that_ME_is_a_backdoor https://en.wikipedia.org/wiki/Intel_Management_Engine#Assert... Look at the last paragraph. Intel usually document everything, but that thing they refuse...
- MerelyMortal 5y agoIntel's quote saying that they do not do that, nor do they have access, could be true. However their statements allow for the possibility that someone else designs backdoors, puts them in, and can use them. > "Intel does not and will not design backdoors for access into its products." > "Intel does not put back doors in its products nor do our products give Intel control or access to computing systems without the explicit permission of the end user." It would be much easier to say, "there are no backdoors", but they don't.
- NikolaeVarius 5y agoI find the name awkward since the "joke" is that the ministry explicitly did the opposite of what the name suggested
- hyperstar 5y ago> Did you know that most modern Intel and AMD computers come with backdoors implanted by the NSA and other agencies? You do now, and it isn’t pretty. The mere possibility that this is true should be enough for us to seek alternatives, but is there any evidence that it is actually the case? My impression was that the Intel Management Engine was a stupid idea but not intended to undermine security.
- TobTobXX 5y agoThere's this great talk from a CCC about reverse engeneering the PSP: Uncover, Understand, Own - Regaining Control Over Your AMD CPU https://www.youtube.com/watch?v=bKH5nGLgi08 https://www.youtube.com/watch?v=bKH5nGLgi08 At 47:10, they mention that they haven't found anything evil. Ofc, this isn't hard proof, but if I trust anyone's answer, then it's theirs. (Btw, watch the whole talk, it's nothing short of incredible.)
- awestroke 5y agoWhat's the deal with GNU plus? I don't care if my coreutils are from GNU, I only care about running a Linux kernel
- marcodiego 5y agoThe girl who runs minifree has had many financial troubles while trying to keep it. I strongly recommend people buying products from people who are willing to make sacrifices to offer a product that respects your freedom. If we do not support people like her, we assume the future risk of having zero costumer really owned devices. Whenever you plan to buy a device and care about not being spied and having control over your owned device, please consider supporting vendors listed here: https://ryf.fsf.org/ https://ryf.fsf.org/
- hammyhavoc 5y agoHow does buying used laptops and installing software on them to then sell to yet another party stop manufacturers preventing this in the future? Why can't people just buy the used laptop made by the big manufacturer and install it themselves? Why trust more third-parties than you absolutely have to?
- Wronnay 5y agoIt seems like the founder also develops libreboot, so by buying a laptop from her you ensure that libreboot keep around.
- Hackbraten 5y agoFlashing custom firmware may be difficult or risky for people with little experience. I can see why one would outsource that service to a vendor.
- LukeShu 5y agoWell, the founder is also the Libreboot founder and lead. The Libreboot releases are signed with her GPG key, she isn't exactly a third party. So, as a sibling comment points out, buying from her helps ensure Libreboot's continued existence. Additionally, in the past (I'm not sure what the financial situation is today), buying from her has also also gone to actually hiring developers to work on Libreboot and port it to more hardware. > Why can't people just buy the used laptop made by the big manufacturer and install it themselves? They can. The founder actually encourages this! At conferences she's run workshops to help people install it themselves.
- prewett 5y agoIf they are going to invoke 1984, it seems like Minifree would be a Windows laptop with WSL installed or something else that has the appearance of freedom while being completely the opposite.
- neilv 5y agoThese prices seem quite reasonable for sourcing a good vintage ThinkPad model (and spec variant) and flashing with Libreboot successfully. If people want to source and flash on their own, it's definitely doable, but IME (as primarily a software person) the difficulty ranges from mild headache to a major one, based on which ThinkPad model and phase of moon. :) https://www.neilvandyke.org/coreboot/ https://www.neilvandyke.org/coreboot/
- NexRebular 5y agoHow's the *BSD support on these ones?
- deleted 5y ago[deleted]